Products
| Product | |
| 1 | runZero Platform |
CVE
CVE-2026-5381Executive summary #
An issue that could expose task information outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorization, and has an estimated CVSS score of CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:N/A:N (2.2 Low). This issue was fixed in version 4.0.260205.0 of the runZero Platform.
Attacker value #
An authorized runZero user could leak information from a limited number of task types from a targeted organization they would not normally have access to. This information could give the attacker some extra insight into the kinds of tasks running in that targeted organization, and some of the data associated with those tasks, which could, in turn, help inform the attacker on tactics that are more likely to be successful.
Credit #
This issue was discovered at runZero during a routine code security review.
Timeline #
2026-02-05 : Issue identified and fixed by the vendor
2026-04-07 : Published this advisory